Skip to content

Malware

Konni

Konni is a remote administration tool, observed in the wild since early 2014.

Konni is a Windows malware family operated by APT37.

Background

Konni is a remote administration tool that has been seen in the wild since the start of 2014. The family is thought to be connected to APT37, a North Korean cyber-espionage group operating since 2012. That group mainly goes after South Korean political organizations, along with targets in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and elsewhere in the Middle East.


Source: Malpedia (Fraunhofer FKIE).